1.2.1-Statement of Need NOI.pdf
PDF 148 KB Posted
- Attached to
- Notice of Intent to Sole Source - TRM Labs Federal contract opportunity
- Solicitation number
- Not on record
- Issued by
- Immigration and Customs Enforcement
About this file
This is a Statement of Need for the Homeland Security Task Force (HSTF) National Coordination Center (NCC) Cyber Disruption Center (CDC) under Executive Order 14390. The CDC requires advanced technology solutions and operational support to address persistent threats from cyber-enabled fraud, ransomware, and sextortion targeting critical infrastructure, financial institutions, and vulnerable populations. The solution must include a team of analysts skilled in cryptocurrency tracing, blockchain analytics, and open-source intelligence tools capable of identifying criminal activity across multiple cryptocurrency blockchains, tracing transactions, recognizing criminal typologies, and producing investigative lead packets with actionable intelligence for federal law enforcement.
The requirement encompasses three primary mission areas: (1) Scam Disruption—including AI-powered triage of victim complaints, automated victim outreach, real-time scam wallet screening, end-to-end asset recovery pipelines, and transnational criminal organization mapping; (2) Cybercrime Disruption and State, Local, Tribal, and Territorial (SLTT) Resilience—featuring unified knowledge bases, indicator of compromise databases with natural-language query interfaces, ransomware asset recovery, and AI-enabled incident response tools for law enforcement and fusion centers; and (3) Sextortion Disruption—involving criminal network targeting, asset tracing across payment rails, expansion to consumer messaging platforms, freeze pipeline integration, and machine learning support for victim identification and perpetrator attribution. The solution must be fully operational and deployable with managed services supporting persistent and scalable disruption capabilities, enabling government personnel to independently operate disruption workflows by the end of implementation. The platform must support rapid operational scaling for surge events and special operations, accommodate forward-deployed personnel and international engagement, and incorporate robust audit, governance, and human-in-the-loop decision frameworks ensuring compliance with privacy and security requirements.
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Statement of Need
The Homeland Security Task Force (HSTF) National Coordination Center (NCC) Cyber Disruption Center (CDC) requires advanced technology solutions and operational support to fulfill its mission under Executive Order 14390. CDC faces persistent and evolving threats from cyber-enabled fraud, ransomware, and sextortion, which target critical infrastructure, financial institutions, and vulnerable populations. Current federal resources and processes are insufficient to match the speed, scale, and sophistication of these adversaries.
To address these challenges, HSTF requires a team of analysts equipped and skilled in cryptocurrency tracing, blockchain analytics, and open-source intelligence tools to identify criminal activity across multiple cryptocurrency blockchains. The analysts must be able to trace transactions, recognize criminal typologies, and produce investigative lead packets with actionable intelligence for federal law enforcement. The support services that enable rapid detection, triage, interdiction, asset recovery, and cross-sector collaboration to support three primary mission areas:
1. Scam Disruption o AI-powered triage of victim complaints and clustering of criminal syndicates.
o Automated victim outreach and support services.
o Real-time scam wallet screening for financial institutions and exchanges.
o End-to-end asset recovery pipeline, including monitoring, tracing, freezing, and forfeiture.
o Targeting and mapping of transnational criminal organizations.
o Verification of victim claims and restitution documentation.
2. Cybercrime Disruption and SLTT Resilience o Unified knowledge base and threat graph for cybercrime, including ransomware and extortion.
o Indicator of compromise (IOC) database and natural-language query interface.
o Intelligence packages to support enforcement actions.
o Ransomware asset recovery and detection of infrastructure overlaps.
o AI-enabled incident response and threat reporting for state, local, tribal, and territorial entities.
o Collaboration tools for law enforcement and fusion centers.
3. Sextortion Disruption o Targeting and mapping of criminal networks and infrastructure operators.
o Asset recovery and tracing of proceeds across payment rails.
o Expansion to consumer messaging platforms and financial institution partners.
o Integration of freeze pipelines and evidence packaging.
o Engineering and machine learning support for victim identification and perpetrator attribution.
o International field engagement and monitoring.
NCC also requires the ability to scale operational capacity rapidly to support surge events, special operations, engineering initiatives, or new partnership activations. The solution must support forward-deployed personnel, international engagement, and participation in mission-related events, in accordance with federal travel regulations.
The NCC seeks a fully operational and deployable platform and managed services that support persistent and scalable disruption capabilities, and enable government personnel to independently operate disruption workflows by the end of the implementation period. The solution must provide robust audit, governance, and human-in-the-loop decision frameworks, ensuring compliance with privacy and security requirements.
File details come from the government source that posted it. Updated .